kura_keyring behaviour (kura v2.17.1)
View SourceBehaviour for supplying the AES-256 keys kura_crypto uses for
at-rest field encryption.
A keyring holds one or more 32-byte keys, each tagged with a key_id
(0-255). New values are encrypted with the active key; any value can
be decrypted by the key whose key_id is embedded in its ciphertext, so
rotation is a matter of adding a new key and flipping active - old rows
keep decrypting under their original key with no backfill.
The default implementation is kura_keyring_env. A regulated deployment
can supply its own module (e.g. reading from a KMS or Vault) by setting
{kura, [{keyring, my_keyring}]} in the application environment.
Summary
Types
A raw 32-byte AES-256 key.
A key identifier, 0-255, embedded in each ciphertext for O(1) lookup.
Types
-type key() :: binary().
A raw 32-byte AES-256 key.
-type key_id() :: 0..255.
A key identifier, 0-255, embedded in each ciphertext for O(1) lookup.
Callbacks
Return the active key (used to encrypt new writes) as {KeyId, Key}, or
undefined if none is configured (encryption then fails loudly).
Return {ok, Key} for KeyId, or error if it is not in the ring.